Thanks for the source, it's interesting that The Telegraph is the only paper reporting this. IOW, I'll believe it when I see it.
The Data Protection Act does not in practice criminalise poor information security – it does criminalise the lack of things like a risk assessment. Short of actual negligence, nobody will be prosecuted due to the hostile actions of a third party. Probably not a bad thing, as it would be obviously ludicrous to do so.
http://www.telegraph.co.uk/news/uknews/terrorism-in-the-uk/1...
>Poor information security isn't a crime.
https://en.wikipedia.org/wiki/Data_Protection_Act_1998
reply